# Fleet v4.60.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2024-11-27 - Version: v4.60.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.60.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.60.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Support for labels_include_any to gitops - **added** — Major improvements to keyboard accessibility throughout app including checkboxes, dropdowns, and table navigation - **added** — Activity item for fleetd enrollment with host serial and display name - **added** — Capability for Fleet to serve YARA rules to agents over HTTPS authenticated via node key (requires osquery 5.14+) - **added** — Query to allow users to turn on/off automations while being transparent of the current log destination - **added** — Better handling of timeout and insufficient permissions errors in NDES SCEP proxy - **added** — Info banner for cloud customers to help with their windows autoenrollment setup - **added** — DB support for include any label profile deployment - **added** — Support for include any label/profile relationships to the profile reconciliation machinery - **added** — team_identifier signature information to Apple macOS applications to the /api/latest/fleet/hosts/:id/software API endpoint - **added** — Indicator of how fresh a software title's host and version counts are on the title's details page - **added** — UI for allowing users to install custom profiles on hosts that include any of the defined labels - **added** — UI features supporting disk encryption for Ubuntu and Fedora Linux - **added** — Support for deb packages compressed with zstd - **changed** — Updated UI to allow users to view scripts from both the scripts page and host details page without downloading them - **changed** — Updated activity feed to generate an activity when activity automations are enabled, edited, or disabled - **changed** — Improved memory usage of the Fleet server when uploading a large software installer file by using temporary disk space - **changed** — Improved performance of adding and removing profiles to large teams by an order of magnitude - **changed** — Updated software batch endpoint status code from 200 (OK) to 202 (Accepted) - **fixed** — Cancelled pending script executions when a script is edited or deleted - **fixed** — Fixed issue with uploading macOS software packages that do not have a top level Distribution.xml but do have a top level PackageInfo.xml - **fixed** — Fixed some cases where Fleet Maintained Apps generated incorrect uninstall scripts - **fixed** — Fixed a bug where a device that was removed from ABM and then added back wouldn't properly re-enroll in Fleet MDM - **fixed** — Fixed name/version parsing issue with PE (EXE) installer self-extracting archives such as Opera - **fixed** — Fixed a bug where the create and update label endpoints could return outdated information in a deployment using a mysql replica - **fixed** — Fixed the MDM configuration profiles deployment when based on excluded labels - **fixed** — Fixed gitops path resolution for installer queries and scripts to always be relative to where the query file or script is referenced - **fixed** — Fixed issue where minimum OS version enforcement was not being applied during Apple ADE if MDM IdP integration was enabled - **fixed** — Fixed a bug where users would be allowed to attempt an install of an App Store app on a host that was not MDM enrolled ##### Fleet 4.60.0 (Nov 27, 2024) ###### Endpoint operations - Added support for labels_include_any to gitops. - Added major improvements to keyboard accessibility throughout app (e.g. checkboxes, dropdowns, table navigation). - Added activity item for `fleetd` enrollment with host serial and display name. - Added capability for Fleet to serve YARA rules to agents over HTTPS authenticated via node key (requires osquery 5.14+). - Added a query to allow users to turn on/off automations while being transparent of the current log destination. - Updated UI to allow users to view scripts (from both the scripts page and host details page) without downloading them. - Updated activity feed to generate an activity when activity automations are enabled, edited, or disabled. - Cancelled pending script executions when a script is edited or deleted. ###### Device management (MDM) - Added better handling of timeout and insufficient permissions errors in NDES SCEP proxy. - Added info banner for cloud customers to help with their windows autoenrollment setup. - Added DB support for "include any" label profile deployment. - Added support for "include any" label/profile relationships to the profile reconciliation machinery. - Added `team_identifier` signature information to Apple macOS applications to the `/api/latest/fleet/hosts/:id/software` API endpoint. - Added indicator of how fresh a software title's host and version counts are on the title's details page. - Added UI for allowing users to install custom profiles on hosts that include any of the defined labels. - Added UI features supporting disk encryption for Ubuntu and Fedora Linux. - Added support for deb packages compressed with zstd. ###### Vulnerability management - Allowed skipping computationally heavy population of vulnerability details when populating host software on hosts list endpoint (`GET /api/latest/fleet/hosts`) when using Fleet Premium (`populate_software=without_vulnerability_descriptions`). ###### Bug fixes and improvements - Improved memory usage of the Fleet server when uploading a large software installer file. Note that the installer will now use (temporary) disk space and sufficient storage space is required. - Improved performance of adding and removing profiles to large teams by an order of magnitude. - Disabled accessibility via keyboard for forms that are disabled via a slider. - Updated software batch endpoint status code from 200 (OK) to 202 (Accepted). - Updated a package used for testing (msw) to improve security. - Updated to reboot linux machine on unlock to work around GDM bug on Ubuntu 24.04. - Updated GitOps to return an error if the deprecated `apple_bm_default_team` key is used and there are more than 1 ABM tokens in Fleet. - Dismissed error flash on the my device page when navigating to another URL. - Modified the Fleet setup experience feature to not run if there is no software or script configured for the setup experience. - Set a more accurate minimum height for the Add hosts > ChromeOS > Policy for extension field, avoiding a scrollbar. - Added UI prompt for user to reenter the password if SCEP/NDES url or username has changed. - Updated ABM public key to download as as PEM format instead of CRT. - Fixed issue with uploading macOS software packages that do not have a top level `Distribution.xml`, but do have a top level `PackageInfo.xml`. For example, Okta Verify.app. - Fixed some cases where Fleet Maintained Apps generated incorrect uninstall scripts. - Fixed a bug where a device that was removed from ABM and then added back wouldn't properly re-enroll in Fleet MDM. - Fixed name/version parsing issue with PE (EXE) installer self-extracting archives such as Opera. - Fixed a bug where the create and update label endpoints could return outdated information in a deployment using a mysql replica. - Fixed the MDM configuration profiles deployment when based on excluded labels. - Fixed gitops path resol _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.60.0]_